CVE-2023-6964: Gutenberg Blocks by Kadence Blocks – Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF)
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadenceimportgetnewconnectiondata' AJAX action. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6964?
CVE-2023-6964 has a medium severity level due to its potential for exploitation via Server-Side Request Forgery.
How do I fix CVE-2023-6964?
To fix CVE-2023-6964, update the Kadence Gutenberg Blocks plugin to version 3.2.12 or later.
Who is affected by CVE-2023-6964?
CVE-2023-6964 affects all versions of the Kadence Gutenberg Blocks plugin up to and including 3.1.26.
What is the attack vector for CVE-2023-6964?
The attack vector for CVE-2023-6964 is the 'kadence_import_get_new_connection_data' AJAX action, allowing authenticated attackers to exploit the vulnerability.
Are all users of the Kadence Gutenberg Blocks plugin vulnerable to CVE-2023-6964?
Yes, all users with versions up to 3.1.26 are vulnerable to CVE-2023-6964 if they have the plugin installed.